Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-88786
HistorySep 30, 2022 - 12:00 a.m.

PHP Denial of Service Vulnerability

2022-09-3000:00:00
China National Vulnerability Database
www.cnvd.org.cn
136
php scripting language
denial of service
vulnerability

0.0005 Low

EPSS

Percentile

18.1%

PHP is a scripting language that executes server-side. a denial of service vulnerability exists in versions of PHP prior to 7.4.31, 8.0.0 and later, 8.0.24 and later, and 8.1.0 and later, and prior to 8.1.11. The vulnerability stems from the fact that the phar decompressor code recursively decompresses quines gzip files, leading to an infinite loop that can be exploited by attackers to The vulnerability can be exploited to launch a denial-of-service attack.